- YouTube warns users of a ongoing phishing scam
- The scam includes a video generated by his CEO.
- Computer pirates are using stolen accounts to transmit cryptography scams
YouTube warns its users of a new Phishing campaign using a video generated by its CEO Neal Mohan as a bait.
On a publication on its official website of the community, the company said it is “aware that Phishers have been sharing private videos to send false videos, including a video generated by the AI of the YouTube CEO, Neal Mohan, announcing changes in monetization.”
“YouTube and its employees will never try to contact or share information through a private video. If a video in private is shared with you, claiming to be from YouTube, the video is a phishing scam, ”said YouTube in the set. “Do not click these links, since the videos will probably lead to phishing sites that can install malware or steal their credentials.”
Victim of the fall
The attack is this: the scammers used AI to create a Deepfake video of the YouTube CEO that discussed the changes in monetization on the platform. Then they shared it as a private video with their goals. In the video description there is a link that takes the victims to the Phishing – Studio.youtube -Plus Destination page[dot]com
There, they are asked to “confirm the updated terms of the YouTube (YPP) partners program”, which continue to monetize their content and access the characteristics of YouTube, but obviously, confirming “the terms, the victims would only share their credentials with the attackers.
In addition, in the true form of Phishing, Crooks added a false emergency sensation, threatening the victims that their accounts will be restricted for a week if they do not meet the new rules. That includes the inability to add videos, receive monetization and more.
Once the victims enter their credentials, the page says the account is in review.
The campaign seems to have been active since the end of January 2025, and “many creators” have already been victims, informing that their channels had been kidnapped and used to broadcast transmissions of live cryptocurrency scams.
Through Bleepingcomputer